Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25032

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

PUBLISHED
Vendor
park_of_ideas
Product
Ricky
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25031

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

PUBLISHED
Vendor
park_of_ideas
Product
Tasty Daily
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25030

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

PUBLISHED
Vendor
park_of_ideas
Product
Goldish
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2503

The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action in all versions up to, and including, 2.3.6. This is due to the user-supplied compare value being placed as an SQL operator in the query without validation against an allowlist of comparison operators. The value is passed through esc_sql(), but since the payload operates as an operator (not inside quotes), esc_sql() has no effect on p

PUBLISHED
Vendor
wpdive
Product
ElementCamp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25029

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

PUBLISHED
Vendor
park_of_ideas
Product
KIDZ
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25028

Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.1.

PUBLISHED
Vendor
Element Invader
Product
ElementInvader Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25027

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.7.1.

PUBLISHED
Vendor
ThemeMove
Product
Unicamp
Provider severity
HIGH
Conflicts
0

CVE-2026-25026

Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11.

PUBLISHED
Vendor
RadiusTheme
Product
Team
Provider severity
HIGH
Conflicts
0

CVE-2026-25025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through <= 1.5.2.

PUBLISHED
Vendor
e4jvikwp
Product
VikRestaurants
Provider severity
HIGH
Conflicts
0

CVE-2026-25024

Cross-Site Request Forgery (CSRF) vulnerability in Blair Williams ThirstyAffiliates thirstyaffiliates allows Cross Site Request Forgery.This issue affects ThirstyAffiliates: from n/a through <= 3.11.9.

PUBLISHED
Vendor
Blair Williams
Product
ThirstyAffiliates
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25023

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP contest-code-checker allows Retrieve Embedded Sensitive Data.This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through <= 2.0.7.

PUBLISHED
Vendor
mdedev
Product
Run Contests, Raffles, and Giveaways with ContestsWP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25022

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16.

PUBLISHED
Vendor
Iqonic Design
Product
KiviCare
Provider severity
HIGH
Conflicts
0

CVE-2026-25021

Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.

PUBLISHED
Vendor
Mizan Themes
Product
Mizan Demo Importer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25020

Missing Authorization vulnerability in WP connect WP Sync for Notion wp-sync-for-notion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sync for Notion: from n/a through <= 1.7.0.

PUBLISHED
Vendor
WP connect
Product
WP Sync for Notion
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2502

The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0, via the 'X-Forwarded-For' HTTP header. This is due to the plugin trusting and logging attacker-controlled IP header data and rendering debug log entries without output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the debug log page.

PUBLISHED
Vendor
yehudah
Product
xmlrpc attacks blocker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25019

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.3.1.

PUBLISHED
Vendor
Vito Peleg
Product
Atarim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25018

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects NaturaLife Extensions: from n/a through <= 2.1.

PUBLISHED
Vendor
stmcan
Product
NaturaLife Extensions
Provider severity
HIGH
Conflicts
0

CVE-2026-25017

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows PHP Local File Inclusion.This issue affects NaturaLife Extensions: from n/a through <= 2.1.

PUBLISHED
Vendor
stmcan
Product
NaturaLife Extensions
Provider severity
HIGH
Conflicts
0

CVE-2026-25016

Missing Authorization vulnerability in Nelio Software Nelio Popups nelio-popups allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nelio Popups: from n/a through <= 1.3.5.

PUBLISHED
Vendor
Nelio Software
Product
Nelio Popups
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25015

Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.53.

PUBLISHED
Vendor
Stiofan
Product
UsersWP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25014

Cross-Site Request Forgery (CSRF) vulnerability in themelooks Enter Addons enteraddons allows Cross Site Request Forgery.This issue affects Enter Addons: from n/a through <= 2.3.2.

PUBLISHED
Vendor
themelooks
Product
Enter Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25013

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a through <= 2.0.8.

PUBLISHED
Vendor
WHMCSdes
Product
Phox Hosting
Provider severity
HIGH
Conflicts
0

CVE-2026-25012

Missing Authorization vulnerability in gfazioli WP Bannerize Pro wp-bannerize-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bannerize Pro: from n/a through <= 1.11.0.

PUBLISHED
Vendor
gfazioli
Product
WP Bannerize Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25011

Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41.

PUBLISHED
Vendor
Northern Beaches Websites
Product
WP Custom Admin Interface
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25010

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.09.

PUBLISHED
Vendor
ILLID
Product
Share This Image
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2501

The Ed's Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `social_share` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
waianaeboy702
Product
Ed's Social Share
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25009

Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Zone: from n/a through <= 1.3.8.

PUBLISHED
Vendor
raratheme
Product
Education Zone
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25008

Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retrieve Embedded Sensitive Data.This issue affects Ninja Tables: from n/a through <= 5.2.5.

PUBLISHED
Vendor
Shahjahan Jewel
Product
Ninja Tables
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25007

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Blind SQL Injection.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.2.

PUBLISHED
Vendor
Element Invader
Product
ElementInvader Addons for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-25006

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through <= 9.6.4.

PUBLISHED
Vendor
8theme
Product
XStore
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25005

Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5.

PUBLISHED
Vendor
N-Media
Product
Frontend File Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25004

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3.

PUBLISHED
Vendor
CreativeMindsSolutions
Product
CM Business Directory
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25003

Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Portal: from n/a through <= 1.2.1.

PUBLISHED
Vendor
madalin.ungureanu
Product
Client Portal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25002

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress – Sepay Payment: from n/a through <= 4.0.0.

PUBLISHED
Vendor
ThimPress
Product
LearnPress – Sepay Payment
Provider severity
HIGH
Conflicts
1

CVE-2026-25001

Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.0.12.

PUBLISHED
Vendor
Saad Iqbal
Product
Post Snippets
Provider severity
HIGH
Conflicts
0

CVE-2026-25000

Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through <= 1.2.0.

PUBLISHED
Vendor
Kraft Plugins
Product
Wheel of Life
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2500

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename` POST parameter directly to `file_get_contents()` without any validation, sanitization, or path restriction. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the server, such as `wp-config.php` or `/etc/passwd`, which can contai

PUBLISHED
Vendor
davidfcarr
Product
Quick Playground
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24999

Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alma: from n/a through <= 5.16.1.

PUBLISHED
Vendor
Alma
Product
Alma
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24998

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hustle wordpress-popup allows Retrieve Embedded Sensitive Data.This issue affects Hustle: from n/a through <= 7.8.9.2.

PUBLISHED
Vendor
WPMU DEV - Your All-in-One WordPress Platform
Product
Hustle
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24997

Missing Authorization vulnerability in Wired Impact Wired Impact Volunteer Management wired-impact-volunteer-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wired Impact Volunteer Management: from n/a through <= 2.8.

PUBLISHED
Vendor
Wired Impact
Product
Wired Impact Volunteer Management
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24996

Missing Authorization vulnerability in wpelemento WPElemento Importer wpelemento-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPElemento Importer: from n/a through <= 0.6.4.

PUBLISHED
Vendor
wpelemento
Product
WPElemento Importer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24995

Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Latest Post Shortcode: from n/a through <= 14.2.0.

PUBLISHED
Vendor
Iulia Cazan
Product
Latest Post Shortcode
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24994

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.7.2.

PUBLISHED
Vendor
sunshinephotocart
Product
Sunshine Photo Cart
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24993

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.3.

PUBLISHED
Vendor
WPFactory
Product
Advanced WooCommerce Product Sales Reporting
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24992

Insertion of Sensitive Information Into Sent Data vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Retrieve Embedded Sensitive Data.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.2.

PUBLISHED
Vendor
WPFactory
Product
Advanced WooCommerce Product Sales Reporting
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24991

Authorization Bypass Through User-Controlled Key vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extensions For CF7: from n/a through <= 3.4.0.

PUBLISHED
Vendor
HT Plugins
Product
Extensions For CF7
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24990

Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through <= 2.2.8.

PUBLISHED
Vendor
Fahad Mahmood
Product
WP Docs
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2499

The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been dis

PUBLISHED
Vendor
tgrk
Product
Custom Logo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-24989

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.

PUBLISHED
Vendor
FantasticPlugins
Product
SUMO Affiliates Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-24988

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Hogg The Events Calendar Shortcode & Block the-events-calendar-shortcode allows Stored XSS.This issue affects The Events Calendar Shortcode & Block: from n/a through <= 3.1.1.

PUBLISHED
Vendor
Brian Hogg
Product
The Events Calendar Shortcode & Block
Provider severity
MEDIUM
Conflicts
0